cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6466
Views
0
Helpful
11
Replies

ASA Firepower Sourcefire cannot add a manager (Firesight)

sk.lachica
Level 1
Level 1

ASA Firepower Sourcefire cannot add a manager (Firesight)

When adding the manager:

 

#configure manager add <firesight-ip> <key>

communication channel for management interface is not configured

 

 

11 Replies 11

Marvin Rhoads
Hall of Fame
Hall of Fame

Is your IP address and other network configuration bits setup and working in the FirePOWER module?

Hi Marvin, 

 

Yes, ip address and default-gateway are setup already. I will ask my team to confirm this and send the screenshot for you.


Thanks!

CCIE (R&S) #27666 CCSI HP MASE

During the sourcefire config process you're prompted to apply the IP and gateway to the management interface.  Why they ask that boggles my mind, the module won't work unless you select yes and apply to the managment interface.

from the module paste the output of show network and show interfaces

They ask that because the FirePOWER module has its own independent routing table (albeit a very basic one) apart from the base ASA.

Yeah I knew about the bridged routing between module and ASA ( a basic verison of how the old 6500 switches with routing modules worked) my point was why ask to apply it as the module will not work without applying the routing to the management interface of the ASA should just auto apply that. I can see many engineers thinking at first glance no I want to reserve management interface for management (go figure right lol)

As for s.lachica a show network and show interfaces from the module CLI will answer just about all our questions.

Actually the base ASA management interface can be configured "no ip address" (and of course "no route management ___" while the FirePOWER module is configured with an address and gateway.

You can use the physical interface for ASA management also but only if it is in the same subnet as the FirePOWER module.

If you're only using the management interface for FirePOWER you can even use the ASA inside interface as the gateway - something you cannot do when you're also using the m0/0 interface for ASA management.

I think of them as two VMs on a hypervisor each with a virtual NIC that maps to the physical m0/0. Only difference is it's not quite as smart as you cannot tag the frames and direct them onto distinct subnets.

One thing coming in the next ASA release will be an actual separate routing table for the management interface on the ASA itself. (pause for applause ;) )

Yes, I have our management interface configured no ip address but it was of little concern as we don't use that interface for management of the boxes. The config script that runs on the module is rather vague and I'm guessing the OP or one of his team configured the IP address and gateway and did not apply it to the management interface. I heard you didnt have to use the management interface for communication to Firesight but I never really chased it down as it was a non issue for us.

bufycisco77
Level 1
Level 1

Hi Guys I have the same problem , any solutions?

can ping manager server (192.168.0.15) is on different subnet no problem

My config on sfr module:

Configure Manager> add 192.168.0.15 key cisco
Communication channel for management interface is not configured!

Configure Manager> system
System> ping 192.168.0.15
PING 192.168.0.15 (192.168.0.15) 56(84) bytes of data.
64 bytes from 192.168.0.15: icmp_req=1 ttl=64 time=10.6 ms
64 bytes from 192.168.0.15: icmp_req=2 ttl=64 time=7.27 ms
64 bytes from 192.168.0.15: icmp_req=3 ttl=64 time=7.64 ms

--- 192.168.0.15 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2002ms
rtt min/avg/max/mdev = 7.271/8.537/10.698/1.537 ms
System> show network
----------------------------------------------------
IPv4
Configuration             : manual
Address                   : 192.168.10.250
Netmask                   : 255.255.255.0
Gateway                   : 192.168.10.1
MAC Address            : F4:CF:E2:C2:63:AC
Management port       : 8305
----------------------------------------------------

Any ideas ?

I have configured this before never had this error.

Thanks

Martin

Hi bufycisco77,

 

Reimage the SFR on the cisco ASA. This resolved our issue last time. Search for the procedure of it in cisco.com, the key command is "recover".

 

Good luck!

Sonny

CCIE (R&S) #27666 CCSI HP MASE

Hi Sonny,

 

yes, I did that. Also I have installed never image 5.4. before it was on 5.3.

And it is all good now.

Thanks

Martin

 

Dinkar Sharma
Cisco Employee
Cisco Employee

This happens due to some issue with sftunnel.conf file (mostly corrupted). You can follow instructions mentioned as per following document.

https://supportforums.cisco.com/discussion/12310476/fail-register-sfr-module

If this does not help, i would suggest to open a TAC case.

Thanks,

Dinkar

Review Cisco Networking for a $25 gift card